Hacker News new | past | comments | ask | show | jobs | submit login

I do think the default a long time ago used to be very low. I know I went in at account creation and set it to something way higher than it's default at the time.

Looking now though, it says 100100 for me. But i also know i changed my master password at some point, so maybe i got reset to the current default.




According to [1], there were 5,000 client-side rounds of SHA256 in key derivation in June 2015.

It does sound like a missed opportunity to have an at-login upgrade mechanism to upgrade KDF rounds that can be carried out seamlessly or near-seamlessly during the login process. Or at least actively nudging users to change password and thus raise their KDF rounds that way through the default.

[1] https://blog.lastpass.com/2015/06/lastpass-security-notice/


One would think that the UI where one routinely enters their master password could silently double as a start using the new default UI, as the change-password UI seemingly does.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: